
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-5157 is a high-severity vulnerability discovered in Google Chrome's Scheduling component. The vulnerability was identified as a Use-After-Free (UAF) issue affecting versions prior to 125.0.6422.76. This security flaw was reported on April 21, 2024, and publicly disclosed on May 21, 2024 (Chrome Release). The vulnerability affects Google Chrome and Chromium-based browsers across Windows, Mac, and Linux platforms (NVD).
The vulnerability is classified as a Use-After-Free (CWE-416) issue in the Scheduling component of Chrome. It has received a CVSS v3.1 base score of 8.8 (HIGH), with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The vulnerability requires user interaction and can be exploited remotely through a specially crafted HTML page (NVD).
If successfully exploited, this vulnerability allows a remote attacker to execute arbitrary code within the browser's sandbox environment. The high CVSS score indicates potential severe impacts on confidentiality, integrity, and availability of the affected system, though the code execution is contained within the sandbox (NVD).
The vulnerability can be triggered through a crafted HTML page, requiring user interaction. The researcher Looben Yang was awarded $11,000 for reporting this vulnerability, indicating its significant security impact (Chrome Release).
Google has released version 125.0.6422.76 of Chrome to address this vulnerability. Users and administrators are advised to update to this version or later. The fix has also been incorporated into Fedora 39 and 40 through the chromium-125.0.6422.76-1 update (Fedora Update).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."